DropsTab logo - blue line depicting the shape of a water drop with Christmas decoration
M. Cap$2.11 T −2.43%24h Vol$151.18 B 29.40%BTC$61,018.16 −2.99%ETH$1,626.15 −2.93%S&P 500$7,356.70 −0.15%Gold$3,995.30 −1.72%BTC Dominance57.79%

Taiko (TAIKO) lost $1.7 million due to a private key that had been lying in public GitHub for two years.

24 Jun, 2026byDropsTab
Join Our Socials

The reason for the Taiko hack turned out to be surprisingly simple: for nearly two years, a file named enclave-key.pem—a RSA private key used to sign all SGX enclaves in the Raiko system—had been sitting in the public repository taikoxyz/raiko. It was this very key that Taiko’s L1 contracts used to verify the authenticity of proofs from L2.

The hacker found the key, registered a fake SGX enclave, signed it with the stolen key—and the contracts accepted it as legitimate. After that, he started sending fraudulent messages through the bridge and withdrawing funds. There were no sophisticated exploits or attacks on smart contracts—simply put, the key had been lying in plain sight for two years.

Continue reading this article on source: github.com